ISO 27001 certification in the UK, with the arithmetic shown
How many audit days the published rule requires for your headcount, what that tends to cost here, and why the body that audits you is barred from being the firm that gets you ready. Tell us how many people are in scope and the numbers appear on this page.
- The audit-day table, published in full. All 22 bands of ISO/IEC 27006-1:2024 Table C.1, from 1 person to 10,700. Most sites in this market summarise it. It is the one number in your quote that is not negotiable.
- Written for the UK. UKAS accreditation, what an accredited certificate actually is, and what happens when a customer checks. The large US platforms cannot write this page.
- Three routes, priced side by side. Toolkit, consultant-led, or a compliance platform. A toolkit vendor leans one way and a platform vendor leans the other. We are paid the same whichever you pick.
Start with the only number that matters
The headcount inside your scope drives the audit days, and the audit days drive the fee. Everything else adjusts around it.
The short version
- Audit days are fixed by a published rule, not by your certification body’s sales team. ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21) gives 22 bands by headcount. A quote that does not reconcile to it needs explaining.
- Surveillance is one third of the initial audit and recertification is two thirds — in every row of the same table. So the ongoing cost is knowable on day one, and it never stops.
- Audit time is never cut by more than 30%, whatever the discount is called. That ceiling is in the rule.
- Your certification body cannot be your consultant. ISO/IEC 17021-1 clause 5.2.5, in terms. If one firm offers you both, something is wrong with one of the offers.
- ISO/IEC 27001:2022 has 93 Annex A controls. Anything still saying 114 is describing the withdrawn ISO/IEC 27001:2013, whose certificates expired on 31 October 2025.
Three roles, and we are none of them
Most of the expensive mistakes in this market start with one misunderstanding: that the firm helping you prepare can also hand you the certificate. It cannot, and the reason is written into the standard that certification bodies are accredited against.
The same diagram as a table
| Role | Does | Cannot do |
|---|---|---|
| Accreditation body (UKAS) | Assesses certification bodies against ISO/IEC 17021-1 and ISO/IEC 27006-1 | Issue you a certificate |
| Certification body | Stage 1, Stage 2, annual surveillance, issues the certificate | Provide management system consultancy to you (clause 5.2.5) |
| Consultancy | Gap analysis, risk assessment, Statement of Applicability, internal audit support | Issue or influence a certificate |
| This site | Publishes the rules and the cost arithmetic; sells advertising | Audit, certify, accredit or advise |
That separation is not a professional courtesy. ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1 is the rule UKAS assesses certification bodies against, and clause 5.2.5 says plainly that the certification body “shall not offer or provide management system consultancy”. Clause 5.2.9 goes further and forbids a certification body from even implying that certification would be “simpler, easier, faster or less expensive” if you used a particular consultancy.
Knowing that changes what you ask for. You are buying two separate things from two separate suppliers, and the second one — the audit — has a price floor set by a published table. How to check a certification body covers what to look for.
We are paid a fixed fee per enquiry, agreed before anyone sends us one. It does not change with the size of your engagement, with which consultancy you pick, or with whether you certify at all. That is the only reason to believe the comparison tables on this site: there is no version of them that pays us more.
What it costs, and which half is actually knowable
Cost questions in this market get answered with a range so wide it is useless — one published UK guide puts implementation at anywhere from £500 to £40,000, an eighty-fold spread. Part of that is honest, because preparation genuinely varies. But it hides the fact that half of the total is set by a rule and can be stated precisely.
The same diagram as a table
| Part | Low | High | Basis |
|---|---|---|---|
| Certification audit | £7,700 | £10,500 | 7 days, from the published table |
| Preparation, consultant-led | £6,000 | £26,400 | 10–22 consultant days |
| Surveillance, per year | £2,550 | £3,500 | 2.33 days, one third of the initial audit |
| First three years | £18,800 | £43,900 | Audit + preparation + two surveillance years |
Day counts come from ISO/IEC 27006-1:2024 Table C.1 and are exact. The money is our estimate built on a day-rate band, rendered as a range and never as a single figure.
The certification audit is arithmetic: find your headcount band in the table, apply any adjustment for sites and complexity within the 30% ceiling the rule allows, multiply by a day rate. We can do the first two exactly and only have to estimate the third. Preparation is the opposite: no published rule, and it is usually the bigger number.
The full cost breakdown works through all four parts with the tables, or the calculator does it for your headcount in one screen.
What you are actually certified against
A surprising amount of published guidance treats ISO 27001 as a list of 93 security controls to implement. It is not. You are certified against clauses 4 to 10 — the management system itself. Annex A is a reference list you select from, and the selection has to be justified in a Statement of Applicability, including the controls you decided not to apply.

The same diagram as a table
| Theme | Reference | Controls | Covers |
|---|---|---|---|
| Organisational | A.5 | 37 | Policies, supplier relationships, incident management, legal and contractual requirements, and the whole of how the ISMS is governed. |
| People | A.6 | 8 | Screening, terms of employment, awareness, disciplinary process, responsibilities after employment ends, and remote working. |
| Physical | A.7 | 14 | Perimeters, entry, equipment siting, clear desk and screen, secure disposal, and physical security monitoring. |
| Technological | A.8 | 34 | Endpoints, access rights, cryptography, logging, secure development, and everything a reader tends to assume the standard is only about. |
| ISO/IEC 27001:2022 total | 93 | Four themes | |
| ISO/IEC 27001:2013 total | 114 | 14 clauses, A.5 to A.18. Withdrawn. | |
That is why two organisations of the same size can have honestly different amounts of work in front of them, and why “how many controls have you got left” is the wrong question to ask a consultant. The controls, theme by theme sets out what is in each one and which are new since 2022.
Start where your question is
- What it costs
- Cost calculator
- UKAS vs non-UKAS
- The process, end to end
- Toolkit, consultant or platform
- The Annex A controls
- Running the ISMS in your own tools
- Choosing a certification body
- ISO 27001 consultants
Common questions
How much does ISO 27001 certification cost in the UK?
It splits into two questions with very different answers. The certification audit itself is predictable: the number of days is set by Table C.1 of ISO/IEC 27006-1:2024, which every accredited certification body works to, and it runs from 5 days for 1 to 10 people up to 28 days for 8,501 to 10,700. At UK day rates that is roughly £7,700 to £10,500 for a 25-person scope. Getting ready is the part that varies, and it is usually the larger number: anywhere from the price of a document toolkit, if you have the people and the time, to £26,400 or more for a consultant-led build at that size. The day counts on this site are exact because they come from a published rule. Every pound figure is our estimate and is labelled as one.
Is iso27001partners.co.uk a certification body?
No, and that distinction matters more here than in most markets. There are three roles: UKAS accredits certification bodies; certification bodies audit you and issue certificates; consultancies help you get ready. We are none of them. We are an independent publisher. We explain what the standards require, publish the audit-day table in full, and run an enquiry form that goes to ISO 27001 consultancies. We cannot issue, arrange or influence a certificate, and nobody who is not accredited can.
Can my consultant also certify me?
No. ISO/IEC 17021-1 clause 5.2.5 says the certification body “shall not offer or provide management system consultancy”, and clause 5.2.7 adds that where a client has taken consultancy from a body related to a certification body, that body must not certify the management system for at least two years afterwards. So the firm that builds your ISMS cannot be the firm that audits it, and if the two are related you may have a two-year problem you did not know about. It is a fair question to ask both of them before you engage either.
What does it cost to use this site?
Nothing, and there is nothing to unlock. Every table, every figure and the calculator are on the page without a form in front of them. Consultancies pay a fixed advertising fee for each enquiry we pass on. That fee is agreed in advance and does not change with the size of the engagement, with whether you certify, or with anything a consultancy charges you.
How many controls does ISO 27001 have?
Annex A of ISO/IEC 27001:2022 lists 93 controls in four themes: organisational (37), people (8), physical (14), technological (34). The withdrawn ISO/IEC 27001:2013 had 114 in 14 clauses. Always check which edition a control count belongs to: a document that says 114 today was written before October 2022. You are certified against clauses 4 to 10, not against Annex A — Annex A is a reference set you select from and justify in a Statement of Applicability.
Do you recommend a particular consultancy?
No, and we are deliberate about that. We do not rank firms, score them or independently vet them. Your enquiry goes to consultancies advertising for your sector and you decide who, if anyone, you speak to. Because our fee is fixed per enquiry rather than taken from what a firm earns, we have nothing to gain from pointing you at one of them.
How long does ISO 27001 certification take?
The audit is the short part. Stage 1 and Stage 2 are separate visits with a gap between them for you to close anything Stage 1 found, and the certificate follows some weeks after the last audit day once the certification body's own review is done. Everything before that — scope, risk assessment, Statement of Applicability, the documented information, an internal audit under clause 9.2 and a management review under clause 9.3 — has no fixed length. Clause 9.2 and 9.3 are the constraint people miss: you cannot sit Stage 2 without having genuinely run both at least once, and that puts a floor under the timeline no amount of budget removes.
Does a certificate from a non-UKAS body count?
It depends entirely on who is asking, and you should find out before you buy one. An accredited certificate comes from a body UKAS has itself assessed against ISO/IEC 17021-1 and ISO/IEC 27006-1, and it carries the UKAS symbol and a published schedule of accreditation naming the scope. A non-accredited certificate is issued by a body nobody has assessed. Both are pieces of paper; only one has anyone standing behind it. Many procurement teams and most public-sector frameworks specify accredited certification explicitly, and a cheaper unaccredited certificate that then fails a customer's check has cost you the whole fee and the time.
Sources cited on this page
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements
- ISO/IEC 27006-1:2024, Requirements for bodies providing audit and certification of information security management systems — Part 1
- ISO/IEC 27006 audit time table, reproduced in full in an accredited certification body's published audit-duration procedure (QSI-TL.04 rev 21)
- BS EN ISO/IEC 17021-1:2015, clause 5.2 (Management of impartiality), full text
- The Accreditation Regulations 2009 (SI 2009/3155), regulation 3
- IAF MD 26:2023, Transition requirements for ISO/IEC 27001:2022
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Get a costed answer, not a call-back to discuss pricing
Five questions, all of them click-only. Your details are the last step, never the first.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.